CVE-2022-46685: Gitea

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credentials masking, potentially exposing them through the build log.

Affected products

  • Gitea Gitea: before 1.4.5 (fixed in 1.4.5)

Published 2022-12-12. Last modified 2026-06-17.